Remix.run Logo
▲ OutOfHere 2 hours ago

Yes, I think captchas are the wrong solution. They annoy all clients, humans included.

IP+subnet based throttling on the other hand is a perfectly working solution, optionally with a proof-of-work or login requirement for intensive POST requests only. Why is it a problem if only a few requests per day are made per home IP? Just how bad and inefficient is the web server?

Bots are not a second class client. They were here before AI, and they, like AI, work for humans. For the most part, they're not trolling the web autonomously.

▲kator 2 hours ago | parent | next [-]

IP blocking doesn't work for bots, they use residential IP addresses and make only one or two requests per IP.

[1] Proposed Amendment to the Telephone Consumer Protection Act of 1991 (2026-05-08) - https://www.karlbunch.com/random/website-protection-act/

▲OutOfHere 2 hours ago | parent [-]

Sorry but the proposal is egregious, considering your website's access far falls short of a DDoS attack against it. You voluntarily host it on the public web. Pay-for-access proposals have existed for decades, and there is a reason they never go anywhere.

Even a $5 VM I have has an included quota of at least 1TB egress data per month, and it can handle 9,540,534 requests in a day if not less. A Rust server can handle a lot more. In practice, my egress quota is larger by virtue of having a couple of more nodes.

If you actually cared, you would use something cheaper then AWS, ideally with zstandard compression, and a CPU efficient service that doesn't buckle under a moderate load.

▲rdevilla an hour ago | parent | prev [-]

[dead]